Beveiligingsadvies

CVE-2026-85608

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 14:32:09
Laatst bijgewerkt 2026-09-04 15:46:12
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages.